On Wed, 13 Jul 2005, David McDowell wrote:

> What do you mean by sanity checking?

You don't want to readfile(/etc/hosts) or
readfile(some-internal-nda-document).  Make sure the parameter is on a
list of permitted files before serving it out.  A
readfile(spreadsheet-with-payroll-information) would be especially
bad, methinks...


-- 
John Berninger
                                                                                
GPG Key ID: A8C1D45C
        Fingerprint: B1BB 90CB 5314 3113 CF22  66AE 822D 42A8 A8C1 D45C

Ita erat quando hic adveni.
--
-- 
TriLUG mailing list        : http://www.trilug.org/mailman/listinfo/trilug
TriLUG Organizational FAQ  : http://trilug.org/faq/
TriLUG Member Services FAQ : http://members.trilug.org/services_faq/
TriLUG PGP Keyring         : http://trilug.org/~chrish/trilug.asc

Reply via email to